Kaspersky Threat Intelligence has introduced new artificial intelligence capabilities and Model Context Protocol support to assist security operations centers. The update simplifies daily operational workflows for analysts who manage large volumes of complex data. Moreover, these automated features process information sourced from more than 25 petabytes of proprietary security telemetry.
Automating Analysis with Single-Click Summaries
Security analysts frequently review hundreds of indicators of compromise and detailed investigation reports during incidents. The new summarization tool condenses these complex records into clear overviews with a single click. Consequently, response teams can evaluate critical items rapidly and determine which events require deeper technical review.
The system automatically selects relevant source datasets to maintain essential investigation context for defenders. In addition, the capability extends to indicators identified through open-source intelligence searches. This ensures that less-experienced personnel can interpret threat records effectively while skilled analysts save operational time.
Model Context Protocol and External AI Connectivity
Support for the Model Context Protocol allows organizations to connect internal and third-party AI applications directly to the portal. Unlike static traditional APIs, this connection format permits language models to execute dynamic queries against live telemetry. As a result, corporate software platforms receive continuous access to global security data.
By standardizing how external systems communicate with underlying threat databases, the protocol simplifies the implementation of custom automation tools. Development teams can build automated triage bots and conversational assistants without creating bespoke data pipelines for each integrated service.
“The primary opportunity we bring with new AI features is to reduce the time between receiving information and understanding how to act on it.”
Alexander Mazikin, Head of Threat Intelligence Product Line at Kaspersky
Expanded Visibility in Kaspersky Threat Intelligence
Automated search features across open-source databases deliver broad visibility into emerging digital risks. Security teams can query specific entities to retrieve structured overviews and prioritize relevant findings. This function strengthens overall cybersecurity defenses by identifying active threats before adversaries execute attacks.
Modern security environments often suffer from alert fatigue due to fragmented data streams. Providing consolidated contextual insights inside Kaspersky Threat Intelligence allows analysts to correlate isolated telemetry points into cohesive incident narratives across corporate networks.
Licensing and Operational Availability
Enterprise customers can access the updated capabilities immediately using standard Kaspersky Threat Lookup licenses. Each license includes a standard allocation of automated query requests. Furthermore, organizations with larger operational demands can scale their quotas by purchasing additional request volume on demand.